Mark RadarMARK RADAR
EN
Event File FINTECH Social Engineering

DigiCert Revokes Leaked EV Code-Signing Certificates After Social-Engineering Attack

1 reports · First detected 2026-05-05 · Last active 2026-05-05

DigiCert is a major global digital certificate authority, and extended validation code signing is used to verify software publishers' identities and help operating systems assess whether programs can be trusted. In this incident, attackers breached a customer-support endpoint through social engineering, enabling them to use legitimate certificates to authenticate malware. The compromise also exposed personnel and access-control risks in the certificate supply chain.

On April 2, 2026, attackers impersonated a customer and sent a ZIP file disguised as a screenshot, tricking DigiCert support staff into running a .scr file. The company discovered on April 14 that another endpoint had been compromised and that initialization codes had been stolen and used to sign Zhong Stealer. DigiCert revoked 60 certificates between April 14 and 17, disabled high-risk access and strengthened multi-factor authentication (MFA). It has not disclosed any financial losses.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)